[Oisf-devel] Suricata rule for finding packets without flags set ?

Victor Julien victor at inliniac.net
Fri Jun 24 05:47:43 UTC 2016


On 23-06-16 12:04, Sherine Davis (Security Engineering) wrote:
> It would be great if someone could tell me the rule that can be used to
> check for packets with null flags ?

A rule with 'flags:0;' should do it I think.

-- 
---------------------------------------------
Victor Julien
http://www.inliniac.net/
PGP: http://www.inliniac.net/victorjulien.asc
---------------------------------------------




More information about the Oisf-devel mailing list